GHSA-v3gr-w9gf-23cx
HIGHCVE-2025-55009Before 0.15.0, @workos-inc/authkit-remix returned sensitive authentication artifacts from the authkitLoader, specifically sealedSession and accessToken. Because these values were returned from the loader, they were embedded into the server-rendered HTML and became readable by any script with access to the page’s DOM (e.g., in the presence of XSS or a malicious browser extension).
- Affected
- < 0.15.0
- Fixed in
- 0.15.0
- Weakness
- CWE-200
- Published
- 2025-08-08
- Source
- github